CVE-2024-45051
CVSS V2 None
CVSS V3 None
Description
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.
Overview
- CVE ID
- CVE-2024-45051
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-07T20:23:01.955Z
- Last Modified Date
- 2024-10-07T20:23:01.955Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-2vjv-pgh4-6rmq | x_refsource_CONFIRM |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-45051 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45051 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-08 13:28:31 | Added to TrackCVE |